You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
10. Change the DNS resolvers on your router, browser, or OS by following the setup instructions in the UI.
14
-
15
14
11. Select **Go to DNS Location**. Your location will appear in your list of locations.
16
15
17
16
You can now apply [DNS policies](/cloudflare-one/policies/gateway/dns-policies/) to your location using the [Location selector](/cloudflare-one/policies/gateway/dns-policies/#location).
Copy file name to clipboardExpand all lines: src/content/docs/cloudflare-one/policies/gateway/dns-policies/index.mdx
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -426,7 +426,7 @@ Use this selector to filter based on the country where the query arrived to Gate
426
426
427
427
### Third-party filtering conflict
428
428
429
-
Gateway will not properly filter traffic sent through third-party VPNs or other Internet filtering software, such as [iCloud Private Relay](https://support.apple.com/102602). To ensure your DNS policies apply to your traffic, we recommend restricting software that may interfere with Gateway.
@@ -12,26 +11,15 @@ The fastest way to start filtering DNS queries from a location is by changing th
12
11
To add a DNS location to Gateway:
13
12
14
13
1. In [Zero Trust](https://one.dash.cloudflare.com), go to **Gateway** > **DNS Locations**.
15
-
16
14
2. Select **Add a location**.
17
-
18
15
3. Choose a name for your DNS location.
19
-
20
16
4. Choose at least one [DNS endpoint](/cloudflare-one/connections/connect-devices/agentless/dns/locations/#dns-endpoints) to resolve your organization's DNS queries.
21
-
22
17
5. (Optional) Toggle the following settings:
23
-
24
-
***Enable EDNS client subnet** sends a user's IP geolocation to authoritative DNS nameservers. <GlossaryTooltipterm="EDNS Client Subnet (ECS)"link="/cloudflare-one/glossary/?term=ecs">EDNS Client Subnet (ECS)</GlossaryTooltip> helps reduce latency by routing the user to the closest origin server. Cloudflare enables EDNS in a privacy preserving way by not sending the user's exact IP address but rather a `/24` range which contains their IP address.
25
-
26
-
***Set as Default DNS Location** sets this location as the default DoH endpoint for DNS queries.
27
-
18
+
-**Enable EDNS client subnet** sends a user's IP geolocation to authoritative DNS nameservers. <GlossaryTooltipterm="EDNS Client Subnet (ECS)"link="/cloudflare-one/glossary/?term=ecs">EDNS Client Subnet (ECS)</GlossaryTooltip> helps reduce latency by routing the user to the closest origin server. Cloudflare enables EDNS in a privacy preserving way by not sending the user's exact IP address but rather a `/24` range which contains their IP address.
19
+
-**Set as Default DNS Location** sets this location as the default DoH endpoint for DNS queries.
28
20
6. Select **Continue**.
29
-
30
21
7. (Optional) Turn on source IP filtering for your configured endpoints, then add any source IPv4/IPv6 addresses to validate.
31
-
32
-
* Endpoint authentication is required for standard IPv4 addresses and optional for dedicated IPv4 addresses.
33
-
***DoH endpoint filtering & authentication** lets you restrict DNS resolution to only valid identities or user tokens in addition to IPv4/IPv6 addresses.
34
-
22
+
- Endpoint authentication is required for standard IPv4 addresses and optional for dedicated IPv4 addresses.
23
+
-**DoH endpoint filtering & authentication** lets you restrict DNS resolution to only valid identities or user tokens in addition to IPv4/IPv6 addresses.
35
24
8. Select **Continue**.
36
-
37
25
9. Review the settings for your DNS location, then choose **Done**.
Gateway will not properly filter traffic sent through third-party VPNs or other Internet filtering software, such as [iCloud Private Relay](https://support.apple.com/102602). To ensure your DNS policies apply to your traffic, Cloudflare recommends turning off software that may interfere with Gateway.
6
+
7
+
To turn off iCloud Private Relay, refer to the Apple user guides for [Mac](https://support.apple.com/guide/mac-help/use-icloud-private-relay-mchlecadabe0/mac) or [iPhone](https://support.apple.com/guide/iphone/protect-web-browsing-icloud-private-relay-iph499d287c2/ios).
0 commit comments